1/* å¤é¾æ§è¡ä»¥æ»¡è¶³ script-srcï¼é¿å æ nonce çå èèæ¬ï¼ï¼nonce ä¸ç¶ç« CSP ä¸è´ */ 2;(function () { 3 var globalNonce = '' 4 var meta = document.querySelector('meta[name="csp-nonce"]') 5 if (meta) { 6 globalNonce = (meta.getAttribute('content') || '').trim() 7 if (/<!--#|echo\s+var/.test(globalNonce)) { 8 globalNonce = '' 9 } 10 } 11 if (!globalNonce && document.currentScript) { 12 var cs = document.currentScript 13 globalNonce = (cs.nonce || cs.getAttribute('nonce') || '').trim() 14 } 15 if (!globalNonce) { 16 var scripts0 = document.getElementsByTagName('script') 17 Array.from(scripts0).some(function (script) { 18 var n = script.nonce || script.getAttribute('nonce') 19 if (n) { 20 globalNonce = n 21 return true 22 } 23 return false 24 }) 25 } 26 if (!globalNonce) { 27 var styles0 = document.getElementsByTagName('style') 28 Array.from(styles0).some(function (style) { 29 var n = style.nonce || style.getAttribute('nonce') 30 if (n) { 31 globalNonce = n 32 return true 33 } 34 return false 35 }) 36 } 37 console.log('è·åå°çnonceå¼ï¼', globalNonce) 38 39 if (!globalNonce) { 40 console.warn('æªæ¾å°ææçnonceï¼æ æ³å¤ç卿æ ç¾') 41 return 42 } 43 44 window.__CSP_NONCE__ = globalNonce 45 window.__webpack_nonce__ = globalNonce 46 47 var origSetAttribute = Element.prototype.setAttribute 48 Element.prototype.setAttribute = function (name, value) { 49 var ln = String(name).toLowerCase() 50 if (ln === 'style' && globalNonce && !this.getAttribute('nonce')) { 51 origSetAttribute.call(this, 'nonce', globalNonce) 52 } 53 return origSetAttribute.call(this, name, value) 54 } 55 56 function wrapInlineStyleNonce (Constructor, label) { 57 if (!Constructor || !Constructor.prototype) return 58 try { 59 var d = Object.getOwnPropertyDescriptor(Constructor.prototype, 'style') 60 if (!d || !d.get) return 61 var innerGet = d.get 62 var styleObjectToProxy = new WeakMap() 63 Object.defineProperty(Constructor.prototype, 'style', { 64 configurable: true, 65 enumerable: d.enumerable !== false, 66 get: function () { 67 var el = this 68 var raw = innerGet.call(el) 69 var cached = styleObjectToProxy.get(raw) 70 if (cached) return cached 71 var proxy = new Proxy(raw, { 72 get: function (target, prop) { 73 if (prop === 'setProperty') { 74 return function (property, value, priority) { 75 if (globalNonce && el.getAttribute && !el.getAttribute('nonce')) { 76 origSetAttribute.call(el, 'nonce', globalNonce) 77 } 78 return target.setProperty.call(target, property, value, priority) 79 } 80 } 81 var v = target[prop] 82 return typeof v === 'function' ? v.bind(target) : v 83 }, 84 set: function (target, prop, val) { 85 if (globalNonce && el.getAttribute && !el.getAttribute('nonce')) { 86 origSetAttribute.call(el, 'nonce', globalNonce) 87 } 88 return Reflect.set(target, prop, val) 89 } 90 }) 91 styleObjectToProxy.set(raw, proxy) 92 return proxy 93 } 94 }) 95 } catch (e) { 96 console.warn('CSP wrap style è·³è¿ ' + label + ':', e) 97 } 98 } 99 wrapInlineStyleNonce(typeof HTMLElement !== 'undefined' ? HTMLElement : null, 'HTMLElement') 100 wrapInlineStyleNonce(typeof SVGElement !== 'undefined' ? SVGElement : null, 'SVGElement') 101 if (typeof MathMLElement !== 'undefined') wrapInlineStyleNonce(MathMLElement, 'MathMLElement') 102 103 var originalCreateElement = document.createElement 104 document.createElement = function (tagName) { 105 var element = originalCreateElement.call(this, tagName) 106 var lowerTagName = String(tagName).toLowerCase() 107 if (lowerTagName === 'script' || lowerTagName === 'style') { 108 origSetAttribute.call(element, 'nonce', globalNonce) 109 if (lowerTagName === 'style') { 110 element.dataset.nonceProcessed = 'true' 111 } 112 } 113 return element 114 } 115 116 var originalCreateTextNode = document.createTextNode 117 document.createTextNode = function (data) { 118 var textNode = originalCreateTextNode.call(this, data) 119 if (typeof data === 'string') {
120 try { 121 var stack = new Error().stack || '' 122 if (stack.indexOf('createTextNode') !== -1 && stack.indexOf('style') !== -1) { 123 var currentNode = textNode 124 var targetStyle = null 125 while (currentNode && currentNode.parentNode) { 126 currentNode = currentNode.parentNode 127 if (currentNode.tagName === 'STYLE') { 128 targetStyle = currentNode 129 break 130 } 131 } 132 if (targetStyle && !targetStyle.getAttribute('nonce')) { 133 origSetAttribute.call(targetStyle, 'nonce', globalNonce) 134 console.log('ä¿®å¤å<style>æå ¥å 容æ¶çnonce缺失') 135 } 136 if (data.trim() === '') { 137 console.warn('æ£æµå°ç©ºæ ·å¼å 容ï¼å·²è·³è¿æå ¥') 138 return originalCreateTextNode.call(this, '/* ç©ºæ ·å¼ */') 139 } 140 } 141 } catch (e) { 142 console.error('å¤çtextNodeæ¶åºéï¼', e) 143 } 144 } 145 return textNode 146 } 147 148 function ensureNodeHasNonce (node) { 149 if (!node || !globalNonce) return 150 if (node.tagName) { 151 var tag = node.tagName.toLowerCase() 152 if (tag === 'style' || tag === 'script') { 153 if (!node.getAttribute('nonce')) { 154 origSetAttribute.call(node, 'nonce', globalNonce) 155 console.log('è¡¥å ' + tag + 'æ ç¾çnonce') 156 } 157 } 158 } 159 if (node.childNodes && node.childNodes.length) { 160 Array.from(node.childNodes).forEach(function (child) { 161 ensureNodeHasNonce(child) 162 }) 163 } 164 } 165 166 var originalAppendChild = Node.prototype.appendChild 167 Node.prototype.appendChild = function (child) { 168 if (this.tagName === 'STYLE') { 169 origSetAttribute.call(this, 'nonce', globalNonce) 170 } 171 ensureNodeHasNonce(child) 172 return originalAppendChild.call(this, child) 173 } 174 175 var originalInsertBefore = Node.prototype.insertBefore 176 Node.prototype.insertBefore = function (child, refNode) { 177 if (this.tagName === 'STYLE') { 178 origSetAttribute.call(this, 'nonce', globalNonce) 179 } 180 ensureNodeHasNonce(child)
181 return originalInsertBefore.call(this, child, refNode) 182 } 183})()
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.